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We conducted an evaluation of DHS' information assurance posture, including its policies and 
procedures, for the intelligence systems under the department's purview. We performed our work 
from May through September 2005, at both the program and organizational component levels. Our 
evaluation focused on DHS' compliance with the Federal Information Security Management Act of 
2002 for its intelligence systems in operation as of May 1, 2005, and containing Top Secret/Sensitive 
Compartmented Information (TS/SCI). 

The overall objective of our evaluation was to identify whether DHS' information security program 
and practices for its intelligence systems are adequate and effective in protecting TS/SCI information 
from unauthorized access, use, disclosure, disruption, modification, or destruction. Our assessment 
included five intelligence community-wide weakness areas that were previously identified by the 
Intelligence Community Chief Information Officer (IC CIO), and three additional areas that the IC 
CIO asked Offices of Inspector General to assess as part of their Fiscal Year 2005 review. As part of 
our evaluation, we also determined whether system security controls were adequate and effective for 
a sample of eight intelligence systems based upon the requirements in Director of Central 
Intelligence Directive 6/3, Protecting Sensitive Compartmented Information Within Information 
Systems. Additionally, we conducted system security vulnerability assessments for a subset of six of 
the eight intelligence systems included in our review. Furthermore, we evaluated DHS' Plan of 
Action and Milestones (POA&M) process for its intelligence systems and followed up on previous 
recommendations discussed with DHS. 

We recommended that DHS establish a single, comprehensive, and inclusive information security 
program for its intelligence systems in order to: (1) address the issues identified; (2) provide 
adequate security for the information and information systems that support intelligence operations 
and assets; and (3) ensure the confidentiality, integrity, and availability of vital intelligence 
information. Both DHS' Office of Security and Assistant Secretary for Information Analysis 
concurred with our recommendation and have begun taking actions to address the issues identified. 
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